Misconfiguration
Misconfigured and dangerous logon scripts
GPO Misconfiguration
PrinterBug
NXC

DNS
ADIDNS SpoofingPassword in description field
PASSWD_NOTREQD Field
Credentials in SMB Shares and SYSVOL Scripts
Group Policy Preferences (GPP) Passwords

Mitigation
ASREPRoasting


Without Credentials - Man-In-The-Middle
AS REPRoastable accounts
PowerView
AD Module
Force Disable Kerberos Preauth
PowerView
BloodyAD
ASREPRoast
Rubeus
HashesNXC
Kerbrute - No creds, but user list
Impacket - No creds, but user list
SharpADWS
ASREPRoast to Kerberoast

Mitigation
Resources
Group Policy Object (GPO) Abuse
PowerView
Built-In Cmdlet
Enumerating Domain User GPO Rights
Exploit Tools - GPOAbuse
Group3r

GPOddity - Exploit GPO through NTLM relay
Resources
Interesting Book
Interesting BooksSupport this Gitbook
Last updated

